Executive brief
Adobe Substance3D Designer, a professional 3D design and modeling application, is vulnerable to a heap-based buffer overflow that allows arbitrary code execution when a user opens a malicious file. An attacker could craft a specially designed file that, when opened by a designer, executes arbitrary code with the victim's user privileges, potentially compromising the system or enabling further attacks.
Technical details
The vulnerability is a heap-based buffer overflow in Adobe Substance3D Designer that can be triggered by processing malicious input files. The attack requires user interaction—specifically, a victim must open a crafted malicious file in the affected application. Upon successful exploitation, an attacker can achieve arbitrary code execution within the security context of the logged-in user. The vulnerability does not require network connectivity or prior authentication and is not reported to be actively exploited in the wild.
Affected products
- Adobe Substance3D Designer
Timeline
- 2026-08-25: disclosed